APPLIED: [SRU][J][PATCH 0/1] CVE-2023-53320
Stefan Bader
stefan.bader at canonical.com
Tue Sep 22 13:32:43 UTC 2026
On 18/09/2026 23:46, Cengiz Can via kernel-team wrote:
> https://ubuntu.com/security/CVE-2023-53320
>
> [ Impact ]
>
> In the Linux kernel, the following vulnerability has been resolved:
>
> scsi: mpi3mr: Fix issues in mpi3mr_get_all_tgt_info()
>
> The function mpi3mr_get_all_tgt_info() has four issues:
>
> 1) It calculates valid entry length in alltgt_info assuming the header part of
> the struct mpi3mr_device_map_info would equal to sizeof(u32). The correct size
> is sizeof(u64).
>
> 2) When it calculates the valid entry length kern_entrylen, it excludes one
> entry by subtracting 1 from num_devices.
>
> 3) It copies num_device by calling memcpy(). Substitution is enough.
>
> 4) It does not specify the calculated length to sg_copy_from_buffer(). Instead,
> it specifies the payload length which is larger than the alltgt_info size. It
> causes "BUG: KASAN: slab-out-of-bounds".
>
> Fix the issues by using the correct header size, removing the subtraction from
> num_devices, replacing the memcpy() with substitution and specifying the
> correct length to sg_copy_from_buffer().
>
> [ Fix ]
>
> jammy/linux: clean cherry-pick of fb428a2005fc
>
> [ Test Plan ]
>
> Build and boot tested.
>
> [ Where Problems Could Occur ]
>
> The change is confined to the mpi3mr driver's handling of the get-all-target
> info driver command, so any regression would surface on systems using Broadcom
> MPI3-based SAS/NVMe storage controllers when userspace queries target
> information. Miscalculating the copy length could return truncated or malformed
> target data to management tools. Systems without mpi3mr hardware are not
> affected.
>
> [ Other Info ]
>
> Kybele flow-v12-15-gbd497840. Reference: c4b57794/v1
>
Applied to jammy:linux/master-next. Thanks.
-Stefan
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20260922/e0ef535a/attachment.sig>
More information about the kernel-team
mailing list